Phying News
Curated security research, vulnerabilities, advisories and tools for practitioners.

CodeBreach: Infiltrating the AWS Console Supply Chain and Hijacking AWS GitHub Repositories via CodeBuild

Summary

CodeBreach: two missing regex characters in AWS CodeBuild pipelines let unauthenticated attackers leak credentials and take over key AWS GitHub repos, including the Console's JavaScript SDK.
Published
Collected

original ↗

Related coverage

back